In Suricata IDS mode. is it possible to block/drop/pass good traffic so it will not be seen in kibana?

Hi MYK,

I haven’t used Kibana myself, so I’m not sure, but could some of the options in ignoring traffic be useful for you, perhaps? There are a few possibilities there, from filtering, to adding pass ou suppress rules, to bypassing traffic… 9.7. Ignoring Traffic — Suricata 7.0.0-dev documentation

Welcome to our forum and let us know if you found something that works for you! :slight_smile: